PatchSiren

Dictionary CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Dictionary CVE published 2026-09-17

CVE-2026-88792

The CVE-2026-88792 vulnerability in the Dictionary WordPress plugin allows unauthenticated users to store arbitrary web scripts, which can be executed when a user views an affected entry. This issue arises from the lack of authorization, sanitization, or escaping in the plugin's dictionary entry addition and update processes. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Affec [truncated]